Your Voice AI Vendor Has a Great Demo. Here’s What to Ask After It Ends.
The infrastructure questions that separate accountable voice AI vendors from demo-day performers.
Every vendor at HIMSS this spring had a compelling story. Intelligent virtual assistants that schedule appointments, verify insurance, and route calls, all without touching a phone tree. Agentic AI that handles multi-step patient workflows autonomously, around the clock. The demos were polished. And honestly, in a controlled environment, the technology usually works exactly as shown.
The problem is that healthcare voice infrastructure doesn’t live on a conference floor. It lives in the telephony environment, the EHR integration layer, and the call queue on a Monday morning when patient volume spikes and your primary recognition environment has an issue. I’ve been deploying and managing healthcare voice systems for more than two decades, at health systems of all sizes, and across a wide range of EHR environments. The questions that matter most almost never come up during a demo.
Here is what I’d recommend asking before you sign anything.
What Happens During the Cutover?
Transitioning a live healthcare contact center from one voice platform to another is one of the highest-risk moments in any deployment. You’re redirecting patient call traffic, potentially tens of thousands of calls per week, from a system that works to a system that should work. The window matters. The redundancy matters. Whether the vendor has done this before, at your scale, with your EHR, in your specific call volume environment. All of those matters.
There is no standard approach to a healthcare voice cutover because no two environments are the same. It could be a SIP trunk migration, a full telco carrier change, remote call forwarding, DID porting, or some combination of all of the above. Each method carries its own sequencing requirements, its own failure modes, and its own rollback constraints. What they all share is the need for meticulous planning and a clear understanding of what the rollback procedure looks like before the first change is made. Low call-volume windows give you flexibility to undo and leave things as they were while you troubleshoot. Vendors who have managed hundreds of live cutovers across these scenarios build that discipline into the plan from day one. Vendors whose primary experience is the demo environment often do not.
Ask your vendor how many live cutovers they’ve managed in healthcare environments comparable to yours. Ask what the rollback procedure is and how long it takes. A good answer is specific, and a vague answer is worth noting.
Who Owns the Outcome After Go-Live?
The governance question for healthcare AI right now is deceptively simple: when something goes wrong six months after deployment, who calls whom? The Health Sector Coordinating Council released a cybersecurity governance guide for AI implementation in June, with the AHA urging every health system to read it, specifically because health systems are deploying AI without always having a clear answer to that question. That’s not a criticism. The vendor landscape has fragmented quickly, and the support models vary enormously.
What you want is a vendor who treats the engagement as a managed service. One where they’re on the hook for uptime, security patching, server lifecycle management, and continuous monitoring, not just the initial deployment. That means they know which servers are running which versions in your environment, what’s coming up for end-of-life, and what the fallback looks like if the primary system has an issue at 2 a.m. on a Saturday. At Parlance, that’s the model we’ve operated under for more than 30 years. We stay in the environment. We manage the infrastructure. We don’t hand it back after go-live and wait for a ticket.
My two cents: a vendor who can’t tell you specifically what their post-go-live support model looks like (who owns monitoring, what the incident response SLA is, how infrastructure changes are communicated and approved) is telling you something important about how the relationship will feel when you actually need them.
Is Your Security Architecture Healthcare-Grade From the Start?
HIPAA compliance is the minimum. The more important question in 2026 is whether a vendor’s security architecture was designed for healthcare from the ground up or retrofitted for it after the product was built. Voice infrastructure in healthcare carries protected health information in transit, patient names, appointment details, insurance information. That data moves across the telephony network, through recognizer environments, through integrations with your EHR. Every handoff is a potential exposure point.
At minimum, you want TLS encryption across every trunk, certificate management handled by the vendor rather than left to your internal team, and a clearly documented process for how PHI is logged, accessed, and retained. Beyond that, ask whether the vendor uses a centralized endpoint security platform across the infrastructure they manage on your behalf, and whether your servers are included in that posture. Ask about their patch cadence for third-party software and their approach to server lifecycle as your operating environments age.
The vendors building demos for trade show floors are not always the vendors who have managed voice infrastructure inside health systems through every security regime change of the last two decades. That experience gap shows up in the architecture. Or it shows up later, in the incident report.
The Bottom Line
The agentic AI market is moving fast, and there is real innovation happening. Health systems should be exploring it. But patient communication infrastructure is not a pilot program, it is a mission-critical function that patients depend on every time they try to reach your organization. A July 2025 MGMA Stat poll found that 71% of medical groups still have fewer than one in four patients using digital tools to schedule appointments. Phone volume in healthcare is not shrinking as fast as some vendors would have you believe.
Find a vendor who can answer your cutover questions with specifics. Who has a documented governance model for post-go-live accountability. Who has managed security infrastructure at health systems comparable to yours in scale and complexity. Who has done it long enough to have built the procedures that prevent the predictable failures.
We are big fans of doing things once and doing them right. That operating principle was not born in a conference session; it was built over 30 years of managing the infrastructure that health systems run on. If you want to talk through what that looks like for your environment, we’re glad to.
Explore the Parlance resource library to understand what questions to ask any voice AI vendor before you deploy.
By Scott Gomes
About the Author
Scott Gomes is Director of Infrastructure and Security at Parlance, where he has led the voice integration of AI deployments at health systems including UW Medicine, Providence Health & Services, and UCLA Health over more than 23 years. He is responsible for the infrastructure that supports every Parlance managed service engagement.